{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-04T13:29:04.364","vulnerabilities":[{"cve":{"id":"CVE-2022-24821","sourceIdentifier":"security-advisories@github.com","published":"2022-04-08T19:15:08.257","lastModified":"2024-11-21T06:51:10.350","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those. This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6. There's no easy workaround for this issue, administrators should upgrade their wiki."},{"lang":"es","value":"La plataforma XWiki es una plataforma wiki genérica que ofrece servicios de tiempo de ejecución para aplicaciones construidas sobre ella. Los usuarios simples pueden crear SSX/JSX globales sin derechos específicos: en teoría, sólo los usuarios con derechos de programación deberían poder crear SSX o JSX que sean ejecutados en cualquier lugar de un wiki. Pero un error permite que cualquiera con derechos de edición pueda crearlos. Este problema ha sido parcheado en XWiki versiones 13.10-rc-1, 12.10.11 y 13.4.6. No se presenta una mitigación fácil para este problema, los administradores deben actualizar su wiki"}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","baseScore":5.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-648"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","versionStartIncluding":"12.0.0","versionEndExcluding":"12.10.11","matchCriteriaId":"F4D7FF74-F74E-4F9A-B40E-91BE45A9A672"},{"vulnerable":true,"criteria":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","versionStartIncluding":"13.4.0","versionEndExcluding":"13.4.6","matchCriteriaId":"D0A3A358-6C84-4C66-B2F1-7F53955BF9A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:xwiki:xwiki:13.10:-:*:*:*:*:*:*","matchCriteriaId":"4B1453B3-C5F1-4C51-8094-FECBBD6F0988"}]}]}],"references":[{"url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-ghcq-472w-vf4h","source":"security-advisories@github.com","tags":["Third Party Advisory"]},{"url":"https://jira.xwiki.org/browse/XWIKI-19155","source":"security-advisories@github.com","tags":["Exploit","Issue Tracking","Patch","Third Party Advisory"]},{"url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-ghcq-472w-vf4h","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://jira.xwiki.org/browse/XWIKI-19155","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Patch","Third Party Advisory"]}]}}]}